MGM Resorts agrees to pay $45M to settle 14 class action lawsuits related to a data breach in 2019 and a ransomware attack the company experienced in 2023
Jonathan Greig / The Record :
Context & Ripple Effects
MGM's exposure spans two distinct failures: a 2019 guest-data breach whose reported scope later grew sharply and a 2023 ransomware incident that disrupted casino and hotel operations. The new agreement puts a single litigation figure around both episodes.
The ransomware attack had already shown that the cost was not limited to data loss: MGM projected more than $100 million in quarterly impact after declining to pay the attackers' ransom. The settlement adds a defined legal cost to that broader disruption.
First-order effects
- MGM takes on a $45 million settlement obligation to resolve 14 class actions tied to the 2019 breach and 2023 ransomware attack.
- The affected plaintiffs gain a negotiated path to resolution, while MGM reduces the uncertainty and administrative burden of litigating the cases separately.
Second-order effects
- Hospitality operators face a clearer example of how a data incident and an operationally disruptive ransomware event can produce overlapping legal costs, not just recovery expenses and lost revenue.
- The outcome reinforces pressure on hotel and casino companies to account for civil-litigation exposure alongside regulatory risk, following Marriott's separate data-security settlements with regulators and states.
Third-order effects
- If comparable cases continue to consolidate multiple incidents into large settlements, cyber-risk planning will increasingly treat customer-data protection and business-continuity failures as connected financial exposures.
- The pattern could make security governance more central to hospitality risk management, though this settlement alone does not establish an industry-wide liability standard.
The trend: Cyber incidents are becoming balance-sheet events that combine outage losses, customer-data claims, and regulatory scrutiny rather than remaining isolated IT costs.